# Why is my search returning all values from time filter

**URL:** <https://discuss.elastic.co/t/why-is-my-search-returning-all-values-from-time-filter/338527>\
**Category:** Elastic Search\
**Tags:** elastic-app-search\
**Created:** [July 17, 2023, 9:47am UTC](https://discuss.elastic.co/t/why-is-my-search-returning-all-values-from-time-filter/338527 "2023-07-17T09:47:27Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![dsmteam](https://avatars.discourse-cdn.com/v4/letter/d/3d9bf3/32.png) [@dsmteam](https://discuss.elastic.co/u/dsmteam)\
**Post date:** [July 17, 2023, 9:47am UTC](https://discuss.elastic.co/t/why-is-my-search-returning-all-values-from-time-filter/338527/1 "2023-07-17T09:47:27Z")

</div>

Hi,  
i'm a bit confused by this simple search

```auto
curl -XGET 'localhost:9200/logstash-*/_count?pretty' -d'		
{
  "query": { 
    "bool": { 
      "should": [
        { "match_phrase": { "Info":"OPTICAL_FIBER_MISCONNECT(l)" }},
        { "match_phrase": { "Info":"LACP_STATE_DOWN(l)" }}
      ],
      "filter": [ 
        { "range": { "@timestamp":{"gte":"now-7d" }}}
      ]
    }
  }
}
' -H 'Content-Type: application/json'

```

Instead of returning a count of documents containing the two values in the should statement, the query will return all values in the time filter despite the timefilter being outside the "should" statement.  
I'm following this exact page except for the "should" instead of "must"

> **[Query and filter context | Elasticsearch Guide \[8.8\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-filter-context.html)**

How should I format my query so I get value shown in the should part and filtered by the timefilter without having all documents in the timefilter ?  
Thanks

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [July 17, 2023, 10:19am UTC](https://discuss.elastic.co/t/why-is-my-search-returning-all-values-from-time-filter/338527/2 "2023-07-17T10:19:35Z")

</div>

I think you need to do something like:

```auto
GET /_count		
{
  "query": {
    "bool": { 
      "filter": [ 
        {     
           "bool": { 
             "should": [
               { "match_phrase": { "Info":"OPTICAL_FIBER_MISCONNECT(l)" }},
               { "match_phrase": { "Info":"LACP_STATE_DOWN(l)" }}
             ]
          }
        },
        { "range": { "@timestamp":{"gte":"now-7d" }}}
      ]
    }
  }
}

```

Not tested... 🙂

---

<div class="post-metadata">

**Author:** ![dsmteam](https://avatars.discourse-cdn.com/v4/letter/d/3d9bf3/32.png) [@dsmteam](https://discuss.elastic.co/u/dsmteam)\
**Post date:** [July 17, 2023, 11:25am UTC](https://discuss.elastic.co/t/why-is-my-search-returning-all-values-from-time-filter/338527/3 "2023-07-17T11:25:43Z")

</div>

You are my hero 🙂  
It works as expected now  
Thanks a lot

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 14, 2023, 11:26am UTC](https://discuss.elastic.co/t/why-is-my-search-returning-all-values-from-time-filter/338527/4 "2023-08-14T11:26:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
